Blog
Less formal than Research: notes, half-finished thoughts, and whatever I'm messing with.
The mirror setup from last week's post is gone. In its place: a full Python port that has to agree with the TypeScript original signal for signal, a patched supply-chain vulnerability, and docs restructured so they stop duplicating the same explanation twice.
Cross-checking the authentication header against the delivery path itself, catching links with no domain at all, closing an evasion gap in my own keyword matching, and a print bug where the obvious fix quietly did nothing.
The heuristic engine behind /phish-report is now its own open-source npm package with a real release pipeline behind it, and a local indicator database is next.
Adding attachment hashing, reply-thread hijack detection, and a Sigma rule that actually uses the hash, then finding a real bug on the way that had nothing to do with any of it.
A review of my own site turned up three live bugs in the phishing analyzer, then a scoring model that was quietly wrong, then a tool that could list indicators but not reason about them.
Converting the whole Express app from plain JS to TypeScript, and the handful of sharp edges that came with it.
Why this section exists separately from Research, and what's actually going to end up here.
What started as a broken deploy turned into a security audit, a new Blog section, and a pile of infrastructure cleanup.